If you were a patient, former patient, guarantor, or employee of Capital Health Systems and your private information was stored on their IT systems during the November 2023 cyberattack, you likely qualify for a piece of the $4.5 million settlement fund. Eligible class members can claim up to $5,000 for documented losses, a flat $100 cash payment with no documentation required, or three years of free credit monitoring. The claim filing deadline is April 6, 2026, and claims can be submitted through the official settlement website at capitalhealthdatabreachsettlement.com. The underlying breach was severe by any measure. The LockBit ransomware group claimed responsibility for the attack, which caused a full IT systems outage at Capital Health from November 11 through November 26, 2023.
During that window, attackers accessed and exfiltrated files containing names, Social Security numbers, dates of birth, medical information, and other sensitive data belonging to more than 503,000 individuals. The case, formally titled *In re: Capital Health Data Breach Litigation*, Case No. 3:23-CV-1418, was filed in the U.S. District Court for the District of New Jersey and resulted in the current $4.5 million settlement.
Table of Contents
- Who Qualifies for the Capital Health Data Breach Settlement and How Do You Know If You’re Eligible?
- What the LockBit Ransomware Group Actually Stole and Why It Matters for Your Claim
- Breaking Down the Three Payment Options Available to Class Members
- How to File Your Claim Before the April 2026 Deadline
- Key Deadlines and What Happens If You Miss Them
- How the Breach Disrupted Capital Health’s Medical Services
- What This Settlement Signals for Healthcare Data Breach Accountability
- Frequently Asked Questions
Who Qualifies for the Capital Health Data Breach Settlement and How Do You Know If You’re Eligible?
The settlement class includes all persons whose private information was potentially compromised in the Capital Health data breach between November 11 and November 26, 2023. That covers a broad group: patients, former patients, guarantors (people financially responsible for a patient’s account), and employees of Capital Health Systems Inc. If your information was stored on Capital Health’s IT systems during the breach window, you are a class member regardless of whether your data was actually misused. For example, if you had an outpatient radiology appointment at Capital Health in 2022 and your records were still in their system at the time of the attack, you would qualify even though your visit was more than a year before the breach occurred.
Capital Health reported the breach to the HHS Office for Civil Rights as affecting 503,071 individuals. Most people who qualify should have already received a notice by mail or email. However, not receiving a notice does not necessarily mean you are excluded. If you believe your information was in Capital Health’s systems during the breach period, you can visit capitalhealthdatabreachsettlement.com to check your eligibility or contact the settlement administrator directly. The key question is not whether your data was confirmed stolen, but whether it was potentially compromised, a much lower bar that works in claimants’ favor.

What the LockBit Ransomware Group Actually Stole and Why It Matters for Your Claim
The LockBit ransomware group did not follow the typical ransomware playbook. Rather than encrypting Capital Health’s files and holding them for ransom, LockBit said they purposely avoided encryption and instead focused entirely on data exfiltration. They claimed to have stolen over 10 million files totaling more than 7 terabytes of data. That distinction matters because it means the stolen information was not just locked in place but actively removed from Capital Health’s environment and potentially distributed or sold on dark web marketplaces.
The types of data compromised include names, addresses, Social Security numbers, dates of birth, email addresses, telephone numbers, and clinical and medical information. That combination is particularly dangerous because it gives bad actors nearly everything they need for full-spectrum identity theft, from opening fraudulent credit lines using your Social Security number to committing medical identity fraud using your clinical records. However, if your relationship with Capital Health was limited, say you were listed only as an emergency contact on someone else’s file, your exposure may be more narrow. The settlement does not distinguish between levels of data exposure, so even partial exposure qualifies you, but understanding what was taken helps you assess your personal risk and decide which payment option to pursue.
Breaking Down the Three Payment Options Available to Class Members
The settlement offers three distinct forms of compensation, and understanding the differences will help you maximize what you receive. Cash Payment A covers documented out-of-pocket losses up to $5,000 per class member. This includes costs related to identity theft, fraudulent charges, credit monitoring services you purchased on your own, and professional fees such as hiring an identity theft resolution service. To claim this amount, you need receipts, account statements, or other third-party records. Self-prepared documents alone, like a handwritten log of your time spent dealing with fraud, are not sufficient. For example, if you paid $30 per month for a credit monitoring subscription after the breach and spent $200 on a credit freeze service, you would submit those billing statements as documentation for a Cash Payment A claim.
Cash Payment B is a flat $100 payment available to class members who did not experience documented losses or simply do not want to go through the documentation process. This is a no-hassle option, but it comes with a caveat: the $100 figure is subject to pro rata adjustment depending on how many people file claims. If the total claims exceed the fund’s capacity, each person’s $100 could shrink. In large data breach settlements, this kind of adjustment is common, though the actual reduction depends entirely on participation rates. All class members, regardless of which cash payment they choose, can also receive three years of free credit monitoring valued at approximately $90 per year. You can elect credit monitoring on its own or in combination with either cash payment option. Given that stolen data can surface on dark web markets years after a breach, the monitoring benefit has real practical value beyond its dollar figure.

How to File Your Claim Before the April 2026 Deadline
Filing a claim requires visiting the official settlement website at capitalhealthdatabreachsettlement.com, where you can submit your claim form online. You will need your notice ID if you received a settlement notice, along with personal identifying information to verify your class membership. For Cash Payment A claims, you will also need to upload supporting documentation such as bank statements showing fraudulent charges, receipts for credit monitoring services, or invoices from identity theft resolution providers. The tradeoff between Cash Payment A and Cash Payment B comes down to effort versus payout.
Cash Payment A can yield up to $5,000 but requires real documentation and the time to gather it. Cash Payment B gets you $100 (potentially less after pro rata adjustment) with minimal effort. If you experienced even modest documented losses, say $150 in credit monitoring fees and a $50 charge for a credit report, pursuing Cash Payment A is worth the extra work since your claim would exceed the Cash Payment B amount. But if your only concern is the exposure itself and you have not incurred specific costs, Cash Payment B plus the free credit monitoring is a reasonable path. The claim filing deadline is April 6, 2026, and late claims will not be accepted, so do not wait until the last week to gather your documents.
Key Deadlines and What Happens If You Miss Them
Three dates control the trajectory of this settlement, and missing any of them limits your options significantly. The exclusion and objection deadline is March 9, 2026. If you want to opt out of the settlement to preserve your right to sue Capital Health independently, or if you want to formally object to the settlement terms, you must do so by that date. The claim filing deadline is April 6, 2026, which is your last chance to submit a claim form. The final approval hearing is scheduled for July 14, 2026, at which point the court will decide whether to grant final approval and authorize distribution of the funds. A critical warning: if you do nothing, you remain a class member by default but receive no payment.
You also give up your right to sue Capital Health over the breach on your own. This is how most class action settlements work, but it catches people off guard. Doing nothing is not a neutral choice. It means you release your legal claims and get nothing in return. If you believe your individual damages exceed what the settlement offers, opting out before March 9 preserves your ability to pursue independent litigation, though that path is more expensive and uncertain. For most class members with losses under $5,000, filing a claim within the settlement is the more practical route.

How the Breach Disrupted Capital Health’s Medical Services
The cyberattack did not just compromise data. It knocked out Capital Health’s IT systems for more than two weeks, from November 11 through November 26, 2023, disrupting actual medical care. Outpatient radiology, elective surgeries, neurophysiology services, and non-invasive cardiology testing were all affected during the outage.
For patients who had procedures delayed or rescheduled due to the attack, the settlement’s compensation framework may feel inadequate, but the claim process is the same regardless of whether you experienced service disruption or data exposure alone. If you had a scheduled surgery or diagnostic test postponed because of the breach, that experience may be worth documenting in your claim even if it does not directly translate to a higher cash payment. It strengthens the overall record of harm and could be relevant if the court considers the adequacy of the settlement at the July 2026 final approval hearing.
What This Settlement Signals for Healthcare Data Breach Accountability
The $4.5 million settlement in the Capital Health case follows a growing pattern of healthcare organizations facing significant financial consequences for data breaches. With over 503,000 individuals affected and a ransomware group that specifically targeted data exfiltration over encryption, this case highlights a shift in how attackers monetize stolen healthcare data and how courts are responding. Lead counsel Kenneth Grunfeld of Kopelowitz Ostrow P.A. and James E. Cecchi of Carella, Byrne, Cecchi, Olstein, Brody & Agnello P.C.
Secured the settlement, adding to a body of precedent that healthcare entities cannot treat cybersecurity as an afterthought. For consumers, the lesson is straightforward. Healthcare providers hold some of the most sensitive data in existence, and breaches in this sector carry uniquely personal risks. If you are a Capital Health class member, file your claim before April 6, 2026. If you are a patient at any healthcare system, take the time to understand what data they hold on you and what protections they have in place. The next breach is not a question of if but when.
Frequently Asked Questions
How do I know if I qualify for the Capital Health data breach settlement?
You qualify if your private information was potentially compromised during the Capital Health cyberattack between November 11 and November 26, 2023. This includes patients, former patients, guarantors, and employees. Most eligible individuals received a notice by mail or email, but you can also check at capitalhealthdatabreachsettlement.com.
What is the deadline to file a claim?
The claim filing deadline is April 6, 2026. Claims submitted after that date will not be accepted. If you want to opt out of the settlement or object to its terms, the deadline for that is earlier: March 9, 2026.
Can I get the $100 cash payment and the credit monitoring?
Yes. The three years of free credit monitoring is available to all class members regardless of whether they choose Cash Payment A (documented losses up to $5,000) or Cash Payment B (the flat $100 payment).
What documentation do I need for the $5,000 claim?
Cash Payment A requires receipts, account statements, or other third-party records showing out-of-pocket losses related to the breach, such as identity theft costs, fraudulent charges, credit monitoring expenses, or professional fees. Self-prepared documents alone are not sufficient.
What happens if I do nothing?
If you take no action, you remain a class member and release your legal claims against Capital Health, but you receive no payment and no credit monitoring. Doing nothing is not a neutral option. You lose both your right to sue and any settlement benefits.
Will I actually receive the full $100 from Cash Payment B?
The $100 amount is subject to pro rata adjustment. If the total number of claims filed exceeds what the settlement fund can cover at $100 per person, each payment will be reduced proportionally. The final amount depends on how many people file claims.
You Might Also Like
- SiriusXM $28 Million Robocall And Telemarketing Settlement: Who Qualifies
- Why Some Settlements Pay Gift Cards Instead of Cash
- Why Settlement Payout Amounts Change After Claims Close
